ImmunixOS 7.0 update for xinetd

From: Immunix Security Team (securityat_private)
Date: Wed Aug 29 2001 - 18:31:09 PDT

  • Next message: Solar Designer: "xinetd 2.3.0 audit status"

    -----------------------------------------------------------------------
    	Immunix OS Security Advisory
    
    Packages updated:	xinetd
    Affected products:	Immunix OS 7.0
    Bugs fixed:		immunix/1698
    Date:			Wed Aug 29 2001
    Advisory ID:		IMNX-2001-70-033-01
    Author:			Seth Arnold <sarnoldat_private>
    -----------------------------------------------------------------------
    
    Description:
      Solar Designer has audited the xinetd 2.3.0 source code for many
      different possible vulnerabilities; the 2.3.1 release represents his
      patches being merged into the standard xinetd source. His audit
      was fairly thorough and found too many problems to report them
      all here. 2.3.2 fixes a heap overrun, with the fix due to Trond
      Eivind Glomsrød. Steve Grubb contributed many other fixes, though
      none appear to be directly security-related.
    
      Suffice it to say that it is only a matter of time before the
      problems fixed here are turned into exploits; we recommend all
      users running xinetd upgrade soon.
    
    
    Package names and locations:
      Precompiled binary packages for Immunix 7.0 are available at:
      http://download.immunix.org/ImmunixOS/7.0/updates/RPMS/xinetd-2.3.3-1_imnx.i386.rpm
    
      Source package for Immunix 7.0 is available at:
      http://download.immunix.org/ImmunixOS/7.0/updates/SRPMS/xinetd-2.3.3-1_imnx.src.rpm
    
    Immunix OS 7.0 md5sums:
      654c1aa4337fbb5752e80d173b186266  RPMS/xinetd-2.3.3-1_imnx.i386.rpm
      2e992bf61ab5439f18e3740a502dc050  SRPMS/xinetd-2.3.3-1_imnx.src.rpm
    
    
    GPG verification:                                                               
      Our public key is available at <http://wirex.com/security/GPG_KEY>.           
      *** NOTE *** This key is different from the one used in advisories            
      IMNX-2001-70-020-01 and earlier.
    
    Online version of all Immunix 6.2 updates and advisories:
      http://immunix.org/ImmunixOS/6.2/updates/
    
    Online version of all Immunix 7.0-beta updates and advisories:
      http://immunix.org/ImmunixOS/7.0-beta/updates/
    
    Online version of all Immunix 7.0 updates and advisories:
      http://immunix.org/ImmunixOS/7.0/updates/
    
    NOTE:
      Ibiblio is graciously mirroring our updates, so if the links above are
      slow, please try:
        ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/
      or one of the many mirrors available at:
        http://www.ibiblio.org/pub/Linux/MIRRORS.html
    
      ImmunixOS 6.2 is no longer officially supported.
    
    Contact information:
      To report vulnerabilities, please contact securityat_private WireX 
      attempts to conform to the RFP vulnerability disclosure protocol
      <http://www.wiretrip.net/rfp/policy.html>.
    
    
    



    This archive was generated by hypermail 2b30 : Wed Aug 29 2001 - 18:52:40 PDT